Weak wallet seeds expose $70 million in bitcoin
thearabianpost.com Aug 1, 2026

Weak wallet seeds expose $70 million in bitcoin

AI-summarised brief · reviewed before publication

On July 30, an attacker siphoned 1,082.65 bitcoin—about $70 million—from 1,196 addresses in a coordinated sweep lasting less than an hour. The theft spanned six Bitcoin blocks, with transfers grouped in batches and pauses between them, indicating pre‑prepared transactions. Galaxy Research traced the flow beyond the initially reported 594 bitcoin loss, revealing that the stolen coins were consolidated into four destination addresses. The breach did not involve malware, physical access, or seed‑phrase interception; instead, it exploited weak randomness in Coldcard hardware‑wallet firmware (versions 4.0.1‑4.1.9 on Mk3 devices and certain Mk4, Mk5, Q models). Faulty firmware fell back on a low‑entropy software source, allowing an offline attacker to generate likely seed phrases, match funded addresses on the blockchain, reconstruct private keys and empty the wallets.

💡 Why It Matters

  • · The incident proves that even air‑gapped hardware wallets can be compromised through flawed firmware, eroding trust in a core security layer of cryptocurrency storage.